CyberSecurity

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

Published

on

Another SharePoint Flaw Under Active Attack

For the fourth time in roughly a month, a SharePoint vulnerability is being exploited in the wild. The latest is CVE-2026-50522, a critical remote code execution bug that Microsoft patched on July 14 as part of its Patch Tuesday releases.

The flaw stems from deserialization of untrusted data. Microsoft’s advisory describes a network-based attack scenario where an authenticated user with at least Site Owner privileges can inject and execute arbitrary code on the SharePoint Server.

Defused, a threat intelligence firm, appears to be the first to spot the exploitation. On July 17, the company reported that its honeypots had detected attempts targeting what looked like a zero-day SharePoint vulnerability. By July 20, Defused had updated its assessment, saying the likely target was CVE-2026-50522.

Things escalated quickly after that. PoC exploit code hit the public, and within a day, security firm WatchTowr confirmed active exploitation.

Attackers Are Stealing Machine Keys

WatchTowr’s analysis paints a concerning picture. Threat actors are pulling SharePoint machine keys with a single request, using them to retain long-term access to compromised systems.

“Attackers are pulling SharePoint machine keys via a single request,” WatchTowr noted, adding, “Patching is not enough; defenders should rotate credentials on any assets that may have been exposed.”

That last point is worth emphasizing. If you’ve already patched, good. But if your SharePoint server was exposed before the patch went on, assume the worst and rotate those keys and credentials.

Microsoft Hasn’t Confirmed Exploitation Yet

Microsoft has not updated its advisory for CVE-2026-50522 to confirm in-the-wild exploitation. That’s not unusual, though. The tech giant often lags behind security researchers in updating advisories after attacks are detected.

It’s a pattern we’ve seen repeatedly with SharePoint vulnerability exploited scenarios this year. The gap between public knowledge and official confirmation can leave defenders guessing about the true scope of the threat.

Three Other SharePoint Bugs Exploited Recently

CVE-2026-50522 isn’t an isolated incident. Three other SharePoint flaws have seen exploitation come to light in recent weeks:

  • CVE-2026-58644
  • CVE-2026-56164
  • CVE-2026-45659

CISA has been warning organizations about attacks targeting SharePoint instances. The agency’s Known Exploited Vulnerabilities (KEV) catalog currently lists 13 SharePoint flaws, five of which were added this year. CVE-2026-50522 has not yet made it onto that list.

What Defenders Should Do Now

If you’re running SharePoint, the math is simple. Patch immediately if you haven’t already. But don’t stop there.

Rotate machine keys and any credentials that might have been exposed. Audit your SharePoint logs for suspicious activity, especially requests that look like they’re pulling configuration data. And keep an eye on CISA’s KEV catalog — if CVE-2026-50522 gets added, that’s a strong signal that federal agencies are being told to treat this as urgent.

The pattern here is clear. Attackers are churning through SharePoint vulnerabilities, and the window between disclosure and exploitation is shrinking. The SharePoint machine keys theft technique WatchTowr documented is particularly nasty because it gives attackers persistence that survives a simple patch.

This wave of attacks should serve as a reminder that patching is just the baseline. For critical infrastructure like SharePoint, assume breach and plan your response accordingly.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version